PT-2024-18680 · Unknown · Artica Proxy

Jim Becher

·

Published

2024-03-05

·

Updated

2024-08-26

·

CVE-2024-2055

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artica Proxy (affected versions not specified)
Description The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass Using an Alternate Path or Channel

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-2055

Affected Products

Artica Proxy